220-1102 Question 735
Single answerInforming management/law enforcement as necessaryA help desk technician receives a call from an employee who reports that their company-issued laptop has been stolen from a locked car while they were traveling. The employee says the laptop contains customer records and asks the technician to remotely wipe it immediately. According to incident response best practices, what should the technician do FIRST regarding notification and escalation?
- A
Notify the employee's manager and the organization's security/incident response team according to company policy before taking further action
- B
Call local law enforcement directly and file a police report on behalf of the employee before informing anyone internally
- C
Remotely wipe the laptop immediately to protect the data, then document the incident later
- D
Postpone reporting until the technician can verify whether the laptop actually contained sensitive data
Show answer and explanation
Correct answer: A
Explanation
The best answer is to notify management and the organization's security/incident response team according to established policy. In A+ Core 2, candidates are expected to understand that suspected security incidents should be handled through documented incident response procedures, including proper escalation and informing management or law enforcement as necessary. A technician should not independently decide to contact police or take potentially destructive actions such as remote wiping unless authorized by policy or directed by incident handlers. Best practices include following the organization's chain of command, documenting the event, preserving evidence where applicable, and allowing designated personnel such as security, legal, compliance, or management to determine whether law enforcement notification is required.
- A. Correct.
Correct. In a potential security incident involving theft and possible exposure of sensitive data, the technician should follow the organization's incident response policy and chain of custody/escalation procedures. That typically means notifying management and the security or incident response team first so the organization can coordinate next steps such as legal review, remote actions, breach assessment, and law enforcement contact if appropriate.
- B. Incorrect.
Incorrect. Although law enforcement may need to be involved, technicians generally should not bypass internal reporting procedures unless company policy explicitly directs them to do so. Management, security, or designated incident handlers typically determine whether and how law enforcement should be contacted.
- C. Incorrect.
Incorrect. Remotely wiping the device may seem protective, but taking unilateral action before proper escalation can interfere with evidence preservation, incident handling, and organizational decision-making. In some cases, the organization may want to attempt tracking, assess whether encryption was enabled, or involve legal/compliance teams first.
- D. Incorrect.
Incorrect. Delaying notification is a common mistake. Even if the data sensitivity is not yet confirmed, a stolen corporate laptop is a reportable security incident that should be escalated promptly. Waiting can increase risk and delay required actions such as account monitoring, device management actions, or compliance review.